Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
bf351f8
Merge pull request #1006 from Automattic/backfill/release-0.11.0
GaryJones Jun 10, 2026
da43258
docs: declare compatibility with WordPress 7.0
GaryJones Jun 10, 2026
10ded34
ci: add a workflow to refresh the wordpress.org readme and assets
GaryJones Jun 10, 2026
248c332
Merge pull request #1007 from Automattic/update/tested-up-to-7-0
GaryJones Jun 10, 2026
22dc0e2
fix: keep post_date_gmt in sync when dragging posts on the calendar
GaryJones Jun 10, 2026
64fa35c
fix: convert quick-create timestamp to GMT when opted in
GaryJones Jun 10, 2026
ca83e3a
Merge pull request #1009 from Automattic/GaryJones/issue-1008-investi…
GaryJones Jun 10, 2026
d88d64d
npm(deps-dev): bump @playwright/test from 1.60.0 to 1.61.0
dependabot[bot] Jun 17, 2026
55e5dba
Merge pull request #1011 from Automattic/dependabot/npm_and_yarn/play…
GaryJones Jun 17, 2026
a69e498
npm(deps-dev): bump form-data from 4.0.5 to 4.0.6
dependabot[bot] Jun 17, 2026
70827dd
npm(deps-dev): bump launch-editor from 2.12.0 to 2.14.1
dependabot[bot] Jun 17, 2026
78df1fa
npm(deps-dev): bump @automattic/eslint-plugin-wpvip from 1.2.1 to 1.3.0
dependabot[bot] Jun 17, 2026
4b74bea
Actions(deps): bump the actions group with 2 updates
dependabot[bot] Jun 22, 2026
6555f9c
npm(deps-dev): bump the dev-dependencies group across 1 directory wit…
dependabot[bot] Jun 24, 2026
b548e70
Merge pull request #1015 from Automattic/dependabot/github_actions/ac…
GaryJones Jun 26, 2026
3bfade8
Merge pull request #1014 from Automattic/dependabot/npm_and_yarn/laun…
GaryJones Jun 26, 2026
187011d
Merge pull request #1013 from Automattic/dependabot/npm_and_yarn/form…
GaryJones Jun 26, 2026
4b58382
Merge pull request #1010 from Automattic/dependabot/npm_and_yarn/dev-…
GaryJones Jun 26, 2026
23f0834
npm(deps): bump qs, @wp-playground/cli and express
dependabot[bot] Jun 26, 2026
25a6a9b
Merge pull request #1017 from Automattic/dependabot/npm_and_yarn/mult…
GaryJones Jun 26, 2026
99f3412
fix: align prettier to wp-prettier@3.0.3 for eslint-plugin-wpvip 1.3.0
GaryJones Jun 26, 2026
3f6887c
Merge pull request #1002 from Automattic/dependabot/npm_and_yarn/auto…
GaryJones Jun 26, 2026
9abde57
npm(deps-dev): bump the dev-dependencies group with 7 updates
dependabot[bot] Jul 1, 2026
b562232
npm(deps-dev): bump webpack-cli from 7.0.3 to 7.1.0
dependabot[bot] Jul 1, 2026
a54de7d
npm(deps): bump downshift from 9.3.6 to 9.4.0
dependabot[bot] Jul 1, 2026
6d23c8c
npm(deps-dev): bump @playwright/test from 1.61.0 to 1.61.1
dependabot[bot] Jul 1, 2026
3bed8a5
npm(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5
dependabot[bot] Jul 15, 2026
7e05e46
npm(deps-dev): bump axios from 1.16.1 to 1.18.1
dependabot[bot] Jul 20, 2026
708a1dc
npm(deps-dev): bump immutable from 5.1.5 to 5.1.9
dependabot[bot] Jul 24, 2026
cf13bd4
npm(deps-dev): bump svgo from 3.3.3 to 3.3.4
dependabot[bot] Jul 24, 2026
d431ea7
npm(deps): bump fast-xml-parser from 5.9.3 to 5.10.1
dependabot[bot] Jul 24, 2026
77e45bf
npm(deps-dev): bump shell-quote from 1.8.4 to 1.10.0
dependabot[bot] Jul 25, 2026
dd16f9f
Actions(deps): bump the actions group across 1 directory with 4 updates
dependabot[bot] Jul 27, 2026
d5d9834
npm(deps-dev): bump postcss from 8.5.15 to 8.5.25
dependabot[bot] Aug 2, 2026
2a5f5fd
npm(deps): bump ip-address from 10.2.0 to 10.4.0
dependabot[bot] Aug 3, 2026
4e413a6
npm(deps-dev): bump fast-uri from 3.1.2 to 3.1.5
dependabot[bot] Aug 5, 2026
2bb8f74
ci: silence two newly-flagged VIPCS sniffs on custom-status code
GaryJones Aug 18, 2026
fee4cff
Merge pull request #1037 from Automattic/GaryJones/fix-cli-nopaging-p…
GaryJones Aug 18, 2026
b5c9f83
fix: stop editorial metadata leaking to REST readers
GaryJones Aug 18, 2026
dbe856c
Merge pull request #1036 from Automattic/GaryJones/rest-editorial-met…
GaryJones Aug 18, 2026
86d0e5c
Merge pull request #1032 from Automattic/dependabot/github_actions/ac…
GaryJones Aug 18, 2026
531e445
Merge pull request #1019 from Automattic/dependabot/npm_and_yarn/dev-…
GaryJones Aug 18, 2026
9043ee7
Merge pull request #1020 from Automattic/dependabot/npm_and_yarn/webp…
GaryJones Aug 18, 2026
79ff8e5
Merge pull request #1021 from Automattic/dependabot/npm_and_yarn/down…
GaryJones Aug 18, 2026
69a0288
Merge pull request #1022 from Automattic/dependabot/npm_and_yarn/play…
GaryJones Aug 18, 2026
5653610
Merge pull request #1024 from Automattic/dependabot/npm_and_yarn/webs…
GaryJones Aug 18, 2026
3c44e98
Merge pull request #1026 from Automattic/dependabot/npm_and_yarn/axio…
GaryJones Aug 18, 2026
d183bd7
Merge pull request #1027 from Automattic/dependabot/npm_and_yarn/immu…
GaryJones Aug 18, 2026
9122e4f
Merge pull request #1028 from Automattic/dependabot/npm_and_yarn/svgo…
GaryJones Aug 18, 2026
1648cf8
Merge pull request #1029 from Automattic/dependabot/npm_and_yarn/fast…
GaryJones Aug 18, 2026
044e9bd
Merge pull request #1031 from Automattic/dependabot/npm_and_yarn/shel…
GaryJones Aug 18, 2026
7fe27a0
Merge pull request #1033 from Automattic/dependabot/npm_and_yarn/post…
GaryJones Aug 18, 2026
33325de
Merge pull request #1034 from Automattic/dependabot/npm_and_yarn/ip-a…
GaryJones Aug 18, 2026
d2330a9
Merge pull request #1035 from Automattic/dependabot/npm_and_yarn/fast…
GaryJones Aug 18, 2026
75a4fde
npm(deps-dev): bump brace-expansion from 1.1.12 to 1.1.18
dependabot[bot] Aug 18, 2026
02252c7
Merge pull request #1038 from Automattic/dependabot/npm_and_yarn/brac…
GaryJones Aug 18, 2026
c596740
docs: declare compatibility with WordPress 7.1
GaryJones Aug 18, 2026
8c7c90c
Merge pull request #1039 from Automattic/GaryJones/tested-up-to-7-1
GaryJones Aug 18, 2026
41422e0
Version 0.11.1 changelog
GaryJones Aug 18, 2026
fefbbcc
Version 0.11.1 i18n
GaryJones Aug 18, 2026
00dfc3b
Version 0.11.1
GaryJones Aug 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,12 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '20'
# Disabled to prevent cache poisoning in release workflows
Expand All @@ -50,7 +50,7 @@ jobs:
SVN_PASSWORD: ${{ secrets.SVN_PASSWORD }}

- name: Upload release asset
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0
uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
with:
files: ${{ github.workspace }}/${{ github.event.repository.name }}.zip
env:
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/e2e-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,12 +50,12 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up NodeJS 20
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '20'
cache: npm
Expand Down Expand Up @@ -95,7 +95,7 @@ jobs:

- name: Cache Playwright browsers
id: playwright-cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ~/.cache/ms-playwright
key: playwright-${{ runner.os }}-${{ steps.playwright-version.outputs.version }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/js-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,12 +40,12 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up NodeJS 20
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: '20'
cache: npm
Expand All @@ -54,7 +54,7 @@ jobs:
run: npm ci

- name: Cache ESLint and Jest results
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
.eslintcache
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/lockfile-registry.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/php-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

Expand All @@ -50,7 +50,7 @@ jobs:
composer-options: --prefer-dist --no-progress

- name: Cache PHPCS results
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .phpcs-cache
key: phpcs-${{ runner.os }}-${{ hashFiles('.phpcs.xml.dist', 'composer.json') }}-${{ github.sha }}
Expand Down
42 changes: 42 additions & 0 deletions .github/workflows/wordpress-org-assets.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
name: Update WordPress.org assets and readme

# Pushes the readme and the .wordpress-org assets (icons, banners, screenshots)
# to the plugin's SVN trunk without cutting a new release. WordPress.org reads
# "Tested up to", "Requires at least" and "Requires PHP" from trunk, so this is
# how those compatibility headers are refreshed between releases. Run it manually
# from the Actions tab after merging a readme or asset change to the default branch.
on:
workflow_dispatch:

# Workflow-level permissions set to none; jobs declare their own minimal permissions
permissions: {}

# Never interrupt an in-flight SVN commit
concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false

jobs:
update:
name: Update readme and assets on WordPress.org
runs-on: ubuntu-latest

permissions:
contents: read # Only needs to read the repository to copy the readme and assets

steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Update readme and assets
uses: 10up/action-wordpress-plugin-asset-update@2480306f6f693672726d08b5917ea114cb2825f7 # v2.2.0
env:
SLUG: edit-flow
SVN_USERNAME: ${{ secrets.SVN_USERNAME }}
SVN_PASSWORD: ${{ secrets.SVN_PASSWORD }}
# This plugin's readme is Markdown (README.md), not the default readme.txt.
README_NAME: README.md
# Only sync the readme and assets; never re-sync the plugin code to trunk.
IGNORE_OTHER_FILES: true
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Editorial workflow plugin with custom statuses, editorial comments, and notifica
| **Function prefix** | `ef_` |
| **Namespace** | Global (legacy) |
| **Source directory** | `modules/` |
| **Version** | 0.11.0 |
| **Version** | 0.11.1 |
| **Requires PHP** | 7.4+ |
| **Requires WP** | 6.4+ |

Expand Down
23 changes: 23 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,28 @@ All notable changes to this project will be documented in this file.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [0.11.1] - 2026-08-18

A maintenance and compatibility release. It closes an information-disclosure issue in the Editorial Metadata module, corrects calendar date handling, declares compatibility with WordPress 7.1, and takes a batch of dependency updates including several security fixes. All users are encouraged to update.

### Security

* fix: stop editorial metadata leaking to unauthorised REST readers by @GaryJones in [#1036](https://github.com/Automattic/edit-flow/pull/1036)

### Fixed

* fix: keep post_date_gmt in sync when dragging posts on the calendar, and convert the quick-create timestamp to GMT when opted in by @GaryJones in [#1009](https://github.com/Automattic/edit-flow/pull/1009)

### Documentation

* docs: declare compatibility with WordPress 7.1 by @GaryJones in [#1039](https://github.com/Automattic/edit-flow/pull/1039)
* docs: declare WordPress 7.0 compatibility and add a wp.org asset-update workflow by @GaryJones in [#1007](https://github.com/Automattic/edit-flow/pull/1007)

### Maintenance

* ci: silence two newly-flagged VIPCS sniffs on custom-status code by @GaryJones in [#1037](https://github.com/Automattic/edit-flow/pull/1037)
* Routine dependency updates for npm packages and GitHub Actions, including security fixes for brace-expansion, axios, postcss, and shell-quote

## [0.11.0] - 2026-06-10

This release completes the security-review remediation begun in 0.10.4. It resolves the remaining issues from a full audit of the plugin's authenticated code paths — the headline stored XSS in the editorial-metadata location field, two information-disclosure issues (the iCal feed and the Story Budget), and a long tail of defence-in-depth hardening across access control, input handling, deserialisation, output escaping, and client-side code. None are known to be exploited in the wild, but all users are encouraged to update.
Expand Down Expand Up @@ -491,6 +513,7 @@ This is a major update with significant bug fixes, new features, and modernised

* Ability to assign custom statuses to posts.

[0.11.1]: https://github.com/Automattic/Edit-Flow/compare/0.11.0...0.11.1
[0.11.0]: https://github.com/Automattic/Edit-Flow/compare/0.10.4...0.11.0
[0.10.4]: https://github.com/Automattic/Edit-Flow/compare/0.10.3...0.10.4
[0.10.3]: https://github.com/Automattic/Edit-Flow/compare/0.10.2...0.10.3
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@ Donate link: http://editflow.org/contribute/
Tags: workflow, editorial, editorial calendar, custom status, newsroom
Requires at least: 6.4
Requires PHP: 7.4
Tested up to: 6.9
Stable tag: 0.11.0
Tested up to: 7.1
Stable tag: 0.11.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Expand Down
4 changes: 2 additions & 2 deletions edit_flow.php
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
* Plugin URI: http://editflow.org/
* Description: Remixing the WordPress admin for better editorial workflow options.
* Author: Daniel Bachhuber, Scott Bressler, Mohammad Jangda, Automattic, and others
* Version: 0.11.0
* Version: 0.11.1
* Requires at least: 6.4
* Requires PHP: 7.4
* License: GPLv2 or later
Expand Down Expand Up @@ -36,7 +36,7 @@ function _ef_print_php_version_admin_notice() {
}

// Define constants.
define( 'EDIT_FLOW_VERSION', '0.11.0' );
define( 'EDIT_FLOW_VERSION', '0.11.1' );
define( 'EDIT_FLOW_ROOT', __DIR__ );
define( 'EDIT_FLOW_FILE_PATH', EDIT_FLOW_ROOT . '/' . basename( __FILE__ ) );
define( 'EDIT_FLOW_URL', plugins_url( '/', __FILE__ ) );
Expand Down
Loading
Loading